Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Cost, Grants and Exposure

The False Claims Act Is Now a Cybersecurity Risk

If you handle defense contracts, the False Claims Act cybersecurity risk is now a direct business concern. The Department of Defense has suspended the CMMC Phase II third party certification requirement as of July 13, 2026, but that does not mean compliance obligations have gone away. Instead, your senior official's signature is now the only assurance standing between your self-assessment and government enforcement. That signature is subject to the False Claims Act if your cybersecurity claims are not accurate.

What is the False Claims Act cybersecurity risk for defense contractors?

The False Claims Act (FCA) allows the government to pursue companies, and even their owners, when false statements are made in order to secure government contracts or payments. In the context of defense contracting, this means that if you certify compliance with cybersecurity requirements, but do not actually meet those requirements, you may be subject to FCA liability.

Recent enforcement actions show that the government is using the FCA to hold companies accountable for misrepresenting their cybersecurity posture. Whistleblowers can also file cases on the government’s behalf, creating another layer of risk.

What did Health Net Federal Services do wrong under the False Claims Act?

Health Net Federal Services falsely certified that it was compliant with required cybersecurity controls on a Defense Health Agency contract. In reality, the company failed to scan for and remediate known vulnerabilities, a core requirement under NIST SP 800-171 Rev 2. This failure meant that its cybersecurity practices did not match what was promised in its contract certification.

The Health Net case demonstrates that simply stating you are compliant, without actual evidence and execution, can lead to FCA exposure. The government expects ongoing vulnerability management, more than paperwork.

What happened in the MORSECORP False Claims Act case?

MORSECORP entered into contracts with the Army and Air Force, claiming to meet NIST SP 800-171 controls. However, the company failed to implement required controls, used non-FedRAMP authorized email systems, and did not have a System Security Plan (SSP) on file.

An SSP is a mandatory document under NIST SP 800-171 Rev 2. It outlines how you meet each control and is a foundational requirement for any defense contractor handling Controlled Unclassified Information (CUI). MORSECORP’s failure to maintain this documentation, combined with inadequate technical controls, led to FCA liability.

Why did Aero Turbine and its private equity owner face False Claims Act liability?

Aero Turbine failed to implement required cybersecurity controls and, more seriously, shared defense data with an unauthorized foreign entity. The FCA settlement in this case extended beyond the company itself, reaching the private equity owner. This demonstrates that liability can follow the ownership chain, more than the operating company.

For business owners, this case is a warning: private equity owners, affiliates, and even subcontractors can be held responsible for cybersecurity misrepresentations. The government is willing to pursue all parties that benefit from a contract based on false cybersecurity claims.

Who can be held liable for False Claims Act cybersecurity violations?

Liability under the False Claims Act is not limited to the company signing the contract. It can extend to:

  • Prime contractors
  • Subcontractors
  • Affiliates
  • Private equity owners

If you are a business owner, operations lead, or investor in a defense contractor, you should understand that your exposure is not limited by organizational structure. If a company in your portfolio or supply chain falsely certifies cybersecurity compliance, you could be named in an FCA action.

What is the impact of the CMMC certification suspension on False Claims Act risk?

On July 13, 2026, the Department of War suspended the CMMC Phase II requirement that a C3PAO certify Level 2 compliance before award. However, all other requirements remain in force:

  • DFARS 252.204-7012
  • NIST SP 800-171 Rev 2
  • Level 1 and Level 2 self-assessments
  • SPRS posting
  • Annual senior official affirmation

With third party certification paused, the government will enforce compliance through self-assessments and select government-led assessments. The key point: the signature of your senior official is now the only assurance of compliance. If that signature is based on inaccurate information or inflated scores, you are at increased risk of FCA action. There is no third party buffer.

What specific cybersecurity requirements must you meet?

If you handle Federal Contract Information (FCI), you must meet Level 1 requirements: 17 practices aligned to FAR 52.204-21 and complete an annual self-assessment.

If you handle Controlled Unclassified Information (CUI), Level 2 applies: 110 controls drawn from NIST SP 800-171 Rev 2. These controls are grouped into 14 families, including Access Control, Audit and Accountability, Configuration Management, and Incident Response. You must:

  • Complete a self-assessment
  • Post your score in SPRS
  • Have a System Security Plan (SSP)
  • Affirm, annually, at the senior official level that your self-assessment is accurate

Every control must be fully met, partial compliance does not count. The government expects a full proof chain: policy, procedure, evidence, and assessment.

How do whistleblowers trigger False Claims Act cases in cybersecurity?

The FCA allows private individuals, known as whistleblowers, to file qui tam actions on behalf of the government. If someone inside your organization or supply chain becomes aware of false cybersecurity certifications, they have a legal path to bring that information forward. This increases the risk that misstatements or gaps will be discovered and prosecuted, even if not found by a government audit.

Common questions

What is the required SPRS score for full NIST SP 800-171 compliance?

A perfect SPRS score is 110, which means all 110 controls are fully met. The average across the defense industrial base is about 60.

Is the CMMC certification deadline still in effect?

No. The requirement for a third party C3PAO to certify Level 2 is suspended as of July 13, 2026. However, all other compliance and self-assessment requirements remain in force.

Can I be held liable if my subcontractor misrepresents cybersecurity compliance?

Yes. FCA liability can extend to primes, subcontractors, affiliates, and private equity owners if false cybersecurity claims are made.

Where can I learn more about official cybersecurity requirements?

You can review official requirements in NIST SP 800-171 Rev 2 and the CMMC Scoping and Assessment Guides L2 v2.13.

How Should Defense Contractors Respond

If your company handles CUI and you are unsure about your NIST 800-171 or CMMC readiness, the Cyber Grants Alliance offers an in kind CMMC Gap Assessment Grant. This grant is delivered as services and covers all 110 NIST 800-171 controls for qualifying defense contractors. Learn more and see if you qualify at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

The False Claims Act cybersecurity risk is real. Accurate self-assessment, complete documentation, and evidence-based compliance are now essential for every defense contractor.

At a glance

The proof chain from policy to assessmentDocumentation shows intent. Evidence proves execution.Policydefines intentProceduredescribes howEvidenceproves executionAssessmentvalidates realityA control is not met because you wrote it down. It is met because you can prove it happened.
The proof chain from policy to assessment

More on Cost and Grants

Cost and Grants · 5 min What CMMC Level 2 Actually Costs

Understand real CMMC cost benchmarks for Level 2, including assessment, remediation, and consulting. Learn how scoping and enclaves affect your budget.